Information processing apparatus, authentication method, authentication program, and patient authentication system

The patient authentication system addresses the challenges of existing technologies by using a unique reception number and personal information for multi-factor authentication, ensuring accurate and secure patient identification.

JP7692318B2Active Publication Date: 2025-06-13GENERAL BREXA TECHNOLOGY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021148749
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-13
Publication Date
2025-06-13
Estimated Expiration
2041-09-13

AI Technical Summary

Technical Problem

Existing patient authentication technologies in hospitals face challenges in accurately and efficiently authenticating patients, particularly due to time-consuming biometric processes and risks associated with single sign-on and one-time password systems, which can be cumbersome for elderly or ill patients.

Method used

A patient authentication system that utilizes a unique 'reception number' issued at the hospital, combined with personal information like date of birth, to perform multi-factor authentication via a cloud service, ensuring accurate patient identification and reducing the risk of misidentification or impersonation.

Benefits of technology

The system enables simple and accurate patient authentication, enhancing security and reducing the risk of medical accidents by leveraging unique hospital-specific information and multi-factor authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007692318000001
    Figure 0007692318000001
  • Figure 0007692318000002
    Figure 0007692318000002
  • Figure 0007692318000003
    Figure 0007692318000003
Patent Text Reader

Abstract

To simply and accurately authenticate the identity of a patient.SOLUTION: A mobile server receives patient information including an identifier which identifies a patient and a receipt number issued when the patient is accepted in a hospital, from a patient terminal used by the patient who has reserved a medical examination to the hospital. The mobile server transmits the patient information, to an in-hospital server which manages reservation information about a person who reserves the medical examination, and requires authentication of the patient who has reserved the medical examination. The mobile server transmits an authentication result by the in-hospital server to the patient terminal.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an authentication method, an authentication program, and a patient authentication system.

Background Art

[0002] In a medical field such as a hospital, not only medical content and examinations by medical staff such as doctors and nurses, but also deficiencies in patient handling at the hospital reception, patient misidentification, and patient impersonation may lead to opportunities for medical accidents, and the risk in case of occurrence is great. As technologies for authenticating the patient himself / herself, biometric authentication, single sign-on, one-time password, etc. are known.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, with the above technologies, it is difficult to easily authenticate that the person is exactly the right one. For example, when performing biometric authentication, a face image, a vein, etc. are imaged and registered by a mobile terminal such as a smartphone or a device installed in the hospital. However, it takes time to image each patient, and re-taking may occur, so it is difficult to easily authenticate.

[0005] Also, in the case of single sign-on using an external server or issuing a one-time password using an in-hospital server, it is premised on issuing to the terminal used by the patient himself / herself, and there is also a risk that authentication may be established even if the issuing destination terminal is a third-party terminal that has already been impersonated, and it is hard to say that the authentication accuracy is high.

[0006] On the one hand, in recent years, the use of a smartphone application for PHR (Personal Health Record) promoted by the Ministry of Internal Affairs and Communications (hereinafter sometimes simply referred to as "app") is assumed. In this app, it is assumed to refer to one's own health information and prescription information of medicine, and functions such as convenient reservation for hospital visits and waiting in line. This app requires information linkage with the hospital's electronic medical record system and needs to authenticate that the user is the person himself / herself. However, with each of the above-described authentication technologies, operations such as camera imaging and sending an empty email for issuing a one-time password occur. In particular, it is troublesome for elderly people or those in poor health to perform, and it is difficult to lead to the popularization of this app.

[0007] One aspect aims to provide an information processing device, an authentication method, an authentication program, and a patient authentication system that can simply and accurately authenticate that the user is the patient himself / herself.

Means for Solving the Problem

[0008] In the first aspect, the information processing device includes: a receiving unit that receives patient information including an identifier for identifying the patient and a reception number issued by the patient receiving at the hospital from a patient terminal used by a patient who has reserved a medical examination at the hospital; a requesting unit that transmits the patient information to an in-hospital server that manages reservation information regarding the person who reserved the medical examination and requests authentication that the user is the patient who reserved the medical examination; and a transmitting unit that transmits the authentication result by the in-hospital server to the patient terminal.

Effect of the Invention

[0009] According to one embodiment, it is possible to simply and accurately authenticate that the user is the patient himself / herself.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Embodiments for Carrying Out the Invention

[0011] Hereinafter, embodiments of the information processing apparatus, authentication method, authentication program, and patient authentication system disclosed in the present application will be described in detail with reference to the drawings. Note that the present invention is not limited by this embodiment. Also, the respective embodiments can be appropriately combined within a non-contradictory range.

Embodiment

[0012] [Overall Configuration] Figure 1 is a diagram showing an overall configuration example of the patient authentication system according to Embodiment 1. As shown in Figure 1, the patient authentication system is a system in which a patient terminal 10 used by patient 1, a mobile server 50, and an in-hospital server 80 managed by hospital 70 are connected via a network N, and is a system that authenticates legitimate patients and provides various services related to medical examinations. Note that the network N can adopt various communication networks such as the Internet and dedicated lines, regardless of whether they are wired or wireless.

[0013] The patient terminal 10 is an example of a terminal device such as a mobile phone or a smartphone used by a patient 1 who makes a reservation for a medical examination at the hospital 70. This patient terminal 10 can utilize various applications, web pages, social networking services (SNS), etc.

[0014] The mobile server 50 is an example of an information processing device that relays communication between the patient terminal 10 and the in-hospital server 80. For example, the mobile server 50 is an information processing device that utilizes a cloud system or the like, and can execute data communication using a specific application with the patient terminal 10.

[0015] The in-hospital server 80 is an example of an information processing device managed by the hospital 70, and is an information processing device that can access a management server that manages the electronic medical records of the hospital 70. For example, the in-hospital server 80 stores reservation information regarding patients who have made reservations for medical examinations.

[0016] The patient authentication system having such a configuration strengthens the method of identity verification by multi-factor authentication using a "reception number" that can only be received by the person himself / herself, which is unique information within the hospital, and a cloud service when receiving a patient who has come to the hospital, provides a mechanism for preventing patient mix-ups, impersonation, and strengthening the management of personal information, and reduces the risk of developing into a medical accident.

[0017] For example, the mobile server 50 receives patient information including an identifier for identifying the patient 1 and a reception number issued when the patient 1 is received at the hospital 80 from the patient terminal 10 used by the patient 1 who has made a reservation for a medical examination at the hospital 70. Then, the mobile server 50 transmits the patient information to the in-hospital server 80 that manages reservation information regarding the reservation maker for the medical examination, requests registration for using the mobile service regarding the medical examination, and transmits the result of the registration by the in-hospital server 70 to the patient terminal 10.

[0018] That is, the mobile server 50 receives patient information necessary for authentication including the "reception number" from the patient terminal 10 and transmits it to the in-hospital server 80. The in-hospital server 80 collates the "patient information" including the "reception number" with the reservation information to authenticate the patient. Then, when the patient terminal 10 is permitted authentication by the in-hospital server 80, mobile services via the mobile server 50 can be used.

[0019] Here, the process until the patient terminal 10 can use mobile services will be described. FIG. 2 is a diagram for explaining the process by the patient authentication system according to the first embodiment. As shown in FIG. 2, the patient 1 makes a reservation for a medical examination at the hospital 70 using the patient terminal 10, a telephone, or the like (S1). For example, the patient 1 conveys the identifier (patient ID), date of birth, department of medicine, and examination date and time described on the examination ticket to the hospital 70, and the hospital 70 registers the reservation information (patient ID, date of birth, department of medicine, examination date and time) in the in-hospital server 80 as reservation information. Note that the patient 1 can also register the reservation information in the in-hospital server 80 using a web browser or a dedicated application, or can register the reservation information in the in-hospital server 80 via a clerk at the hospital 70 using a telephone or the like.

[0020] The patient 1 who has completed the medical examination reservation goes to the hospital 70 on the day of the examination and obtains the reception number given to the patient 1 on the day of the examination printed on the reception ticket issued by inserting the examination ticket of the patient 1 into the re-registration machine 75 installed in the hospital 70 (S2 and S3). For example, the in-hospital server 80 obtains the association between the issued reception number "0001" and the "patient ID" of the examination ticket through communication with the re-registration machine 75 and registers it in the reservation information. That is, the in-hospital server 80 manages the reception number issued for each patient ID.

[0021] After that, in order to use the mobile service, Patient 1 uses the patient terminal 10 to send the "User ID" for identifying the app user and the "Patient Information (Patient ID, Reception Number, Date of Birth)" to the mobile server 50 (S4). Then, the mobile server 50 assigns an "Application ID" to the patient information and stores it in association with the "User ID" and the "Patient Information (Patient ID, Reception Number, Date of Birth)". After that, the mobile server 50 sends the "Application ID" and the "Patient Information (Patient ID, Reception Number, Date of Birth)" to the in-hospital server 80 and requests the authentication of the patient terminal 10 and the registration for using the mobile service (S5).

[0022] Subsequently, the in-hospital server 80 receives the "Application ID" and the "Patient Information (Patient ID, Reception Number, Date of Birth)" from the mobile server 50, and authenticates Patient 1 based on whether the received "Patient Information (Patient ID, Reception Number, Date of Birth)" is registered in the reservation information (S6). If the in-hospital server 80 permits the authentication of Patient 1 because the received patient information is registered in the reservation information, it assigns a "Service Use ID" and registers it in the reservation information, and sends the "Application ID" and the "Service Use ID" to the mobile server 50 in association with each other (S7).

[0023] The mobile server 50 that has received this "Application ID" and "Service Use ID" registers the "Service Use ID" in the patient information associated with the "Application ID", and sends a message to the patient terminal 10 indicating that the registration for using the mobile service has been completed (S8).

[0024] In this way, the in-hospital server 80 accurately authenticates Patient 1, and the use of the mobile service by Patient 1 is permitted between Patient 1 and the in-hospital server 80.

[0025] After that, as a mobile service, the in-hospital server 80 refers to the reservation information of Patient 1, and when the reserved day arrives, it sends a "Message" for notifying the examination and the "Service Use ID" registered in the reservation information of Patient 1 to the mobile server 50 in association with each other (S9).

[0026] Subsequently, the mobile server 50 refers to the patient information, identifies the "user ID" associated with the received "service usage ID", and transmits the received "message" to the patient terminal 10 by means of an SNS message addressed to the "user ID" (S10). As a result, the patient terminal 10 receives and displays the "message" notified by the mobile service.

[0027] As described above, the patient authentication system can simply and accurately authenticate that the user is the patient himself / herself. In addition, after simple and accurate authentication, the patient authentication system can provide mobile services related to medical examinations to legitimate patients.

[0028] [Functional Configuration] Next, the functional configuration of each device constituting the patient authentication system will be described. FIG. 3 is a functional block diagram showing the functional configuration of the patient authentication system according to the first embodiment.

[0029] (Patient Terminal 10) As shown in FIG. 3, the patient terminal 10 includes a communication unit 11, a display unit 12, a storage unit 13, and a control unit 20. The communication unit 11 is a processing unit that controls communication with other devices and is realized, for example, by a communication interface or the like. For example, the communication unit 11 transmits various data to the mobile server 50 and the in-hospital server 80, and receives various data from the mobile server 50 and the in-hospital server 80.

[0030] The display unit 12 is a processing unit that displays various information and is realized, for example, by a display, a touch panel, or the like. For example, the display unit 12 displays and outputs a screen requesting authentication, a screen indicating the result of authentication, various messages, and the like.

[0031] The storage unit 13 is a processing unit that stores various data and programs executed by the control unit 20 and is realized, for example, by a memory, a hard disk, or the like. For example, the storage unit 13 stores a user ID used in an application for performing SNS message communication.

[0032] The control unit 20 is a processing unit that manages the entire patient terminal 10 and is realized by, for example, a processor or the like. This control unit 20 has a registration unit 21 and a usage control unit 22. Note that the registration unit 21 and the usage control unit 22 are realized by an electronic circuit of the processor, a process executed by the processor, or the like.

[0033] Note that the control unit 20 can also make a medical appointment by transmitting patient ID and reservation information to the in-hospital server 80 using a Web screen, an SNS message, a dedicated app, or the like. Without being limited to this, the patient 1 can also make a medical appointment by conveying the information necessary for the medical appointment to the hospital 70 by phone or the like.

[0034] The registration unit 21 is a processing unit that requests the in-hospital server 80 to authenticate that the patient is legitimate and register for mobile services. Specifically, the registration unit 21 transmits a registration request including an identifier for identifying the patient, a reception number issued by the re-reception device 75, and the patient's personal information to the in-hospital server 80 via the mobile server 50, and receives the result of the request from the in-hospital server 80 via the mobile server 50.

[0035] The usage control unit 22 is a processing unit that enjoys the mobile services provided by the in-hospital server 80 when it is authenticated by the in-hospital server 80 as a legitimate patient and the use of mobile services is registered. For example, the usage control unit 22 receives a message transmitted from the in-hospital server 80 via the mobile server 50 by SNS message communication using the user ID.

[0036] Here, the processing of the registration unit 21 and the usage control unit 22 will be described using various screen examples displayed on the display unit 12. FIG. 4 is a diagram showing various screen examples. For example, the registration unit 21 accesses the in-hospital server 80 using a web browser, an SNS message, a dedicated application, etc., and displays the registration screen 10A shown in FIG. 4 on the display unit 12. Then, on the registration screen 10A, the registration unit 21 accepts the input of the patient ID "1111", the reception number "0001", and the date of birth "19891112". When the "send" button is pressed, these patient ID "1111", reception number "0001", and date of birth "19891112" are transmitted as patient information to the mobile server 50. At this time, when the registration unit 21 transmits patient information using a web browser or the like, the user ID "AAAA" is also transmitted together. When using an SNS that has been negotiated with the mobile server 50, since the user ID is included in the SNS message function, there is no need to send the user ID again. Note that "negotiated" means, for example, a state where mutual user registration has been completed, or a state where a common application is used, mutual user registration has been completed, and messages can be sent and received within the application.

[0037] Note that the patient ID is information for identifying the patient printed on the examination ticket, and is also managed in association with the patient's personal information (date of birth, address, age, telephone number, etc.) in the in-hospital server 80. The reception number is the reception number given to Patient 1 on the day of the examination date printed on the reception ticket issued by inserting the examination ticket of Patient 1 into the re-registration machine 75 installed in the hospital 70. The date of birth is an example of the patient's personal information, and in addition to the date of birth, an address, a telephone number, an age, a my number, etc. can also be adopted. Also, the registration on the registration screen 10A may be manually input by Patient 1, or a registration method using captured screen data or a two-dimensional barcode may be adopted.

[0038] After that, when it is confirmed that the user of the patient terminal 10 is a legitimate patient and the registration for using the mobile service is completed, the patient terminal 10 receives the completion screen 10B shown in FIG. 4 from the in-hospital server 80 and displays it on the display unit 12. For example, the completion screen 10B displays a completion notice such as "Registration completed" and the "patient information (patient ID, reception number, date of birth)" entered on the registration screen 10A. By receiving this completion screen 10B, it means that the patient information has been registered in the in-hospital server 80.

[0039] After that, the patient terminal 10 displays a notification screen 10C including the message received from the in-hospital server 80 on the display unit 12. The notification screen 10C displays a message such as "The reserved time is approaching" and the content transmitted by the in-hospital server 80 such as the reservation information "Reservation date and time: September 3, 2021, 14:00, Internal Medicine".

[0040] (Mobile server 50) As shown in FIG. 3, the mobile server 50 includes a communication unit 51, a storage unit 52, and a control unit 60. The communication unit 51 is a processing unit that controls communication with other devices and is realized by, for example, a communication interface. For example, the communication unit 51 transmits various data to the patient terminal 10 and the in-hospital server 80, and receives various data from the patient terminal 10 and the in-hospital server 80.

[0041] The storage unit 52 is a processing unit that stores various data and programs executed by the control unit 20 and is realized by, for example, a memory or a hard disk. For example, the storage unit 52 stores a patient information DB 53.

[0042] The patient information DB 53 is a database that stores information about patient 1. Specifically, the patient information DB 53 stores the destination information for sending SNS messages, the patient information obtained from the patient terminal 10, and the authentication result of patient 1 by the in-hospital server 80 in association with each other. FIG. 5 is a diagram showing an example of the information stored in the patient information DB 53. As shown in FIG. 5, the patient information DB 53 stores "user ID, patient ID (service usage ID), date of birth, reception number, application ID, authentication result".

[0043] The "User ID" stored here is an example of destination information for performing SNS messages, and may be registered through negotiation using the SNS application on the patient terminal 10 and the mobile server 50, or may be obtained from the patient terminal 10 when a certification request or a service usage registration request is made. Among the "Patient ID (Service Usage ID)", the patient ID is an identifier for identifying the patient, and the service usage ID is an identifier used for using the mobile service issued by the in-hospital server 80. The "Date of Birth" is the date of birth of Patient 1, and is an example of the personal information of Patient 1. The "Reception Number" is the reception number issued to Patient 1. The "Application ID" is an identifier for identifying the requester, issued by the mobile server 50 when a service usage registration request for the mobile service is made. The "Certification Result" is the certification result by the in-hospital server 80. For example, "OK" is registered in the case of successful certification, and "NG" is registered in the case of failed certification.

[0044] In the example of FIG. 5, for the user with "User ID = AAAA", the patient ID "1111", the date of birth "19891112", and the reception number "0001" are registered. Since the application ID and the certification result are not registered, it is shown that the certification of the patient and the certification of the service usage registration of the mobile service have not been implemented.

[0045] The control unit 60 is a processing unit that controls the entire mobile server 50, and is realized by, for example, a processor or the like. This control unit 60 includes a reception unit 61, a request unit 62, a transmission unit 63, and a provision unit 64. Note that the reception unit 61, the request unit 62, the transmission unit 63, and the provision unit 64 are realized by an electronic circuit included in the processor, a process executed by the processor, or the like.

[0046] Here, the processing of each processing unit will also be described using the transition of the patient information DB53 shown in FIG. 6. Note that FIG. 6 is a diagram showing the transition of the patient information DB53.

[0047] The receiving unit 61 is a processing unit that receives patient information including a patient ID for identifying patient 1 and a reception number issued by hospital 70 upon receiving a reservation for a medical examination from patient terminal 10 used by patient 1 who has reserved a medical examination at the hospital. For example, the receiving unit 61 receives from patient terminal 10 "User ID: AAAA" and "Patient information (Patient ID: 1111, Reception number: 0001, Date of birth: 19891112)". Then, as shown in Fig. 6(a), the receiving unit 61 stores the received information in patient information DB 53.

[0048] Note that when the receiving unit 61 receives patient information using a web browser or the like, it also receives the user ID "AAAA" transmitted together. However, when receiving patient information using an SNS message function or the like that has been negotiated with patient terminal 10, the user ID can also be obtained from the SNS message.

[0049] The requesting unit 62 is a processing unit that transmits the patient information received by the receiving unit 61 to in-hospital server 80 and executes a request for authentication as a patient who has reserved a medical examination and registration for using mobile services. For example, the requesting unit 62 assigns an application ID "1" to the received patient information (Patient ID: 1111, Reception number: 0001, Date of birth: 19891112). Then, as shown in Fig. 6(b), the requesting unit 62 stores the patient information (Patient ID: 1111, Reception number: 0001, Date of birth: 19891112) stored in patient information DB 53 in association with the assigned application ID "1".

[0050] After that, the request unit 62 transmits the patient information (patient ID: 1111, reception number: 0001, date of birth: 19891112) and the application ID "1" as registration information to the in-hospital server 80, and requests authentication of patient 1 and registration for using the mobile service. Here, as shown in FIG. 6(c), since the patient (user ID: AAAA) can be identified by the application ID, the request unit 62 deletes "patient ID: 1111, reception number: 0001, date of birth: 19891112" transmitted from patient 1 from the patient information DB53. As a result, the mobile server 50 will not store the personal information of patient 1, can act as a relay server that is reassuring and safe for patient 1, and can also maintain high security.

[0051] The transmission unit 63 is a processing unit that transmits the authentication result of patient 1 by the in-hospital server 80 and the response result to the request for registration for using the mobile service to the patient terminal 10. For example, the transmission unit 63 receives from the in-hospital server 80 the authentication result "OK" of patient 1 and the service use ID "XXXXXX" which is the response result of the registration for use, together with the application ID "1" transmitted by the request unit 62.

[0052] Then, as shown in FIG. 6(d), the transmission unit 63 searches the patient information DB53 using the application ID "1" as a key, and registers the service use ID "XXXXXX" in the corresponding patient information. Then, the transmission unit 63 transmits the authentication result "OK" and the permission for service use registration, etc. to the patient terminal 10.

[0053] When the provision unit 64 receives the service use ID and the message to the patient from the in-hospital server 80, it refers to the patient information DB53, identifies the patient terminal 10 associated with the service use ID, and is a processing unit that transmits the message to the patient terminal 10.

[0054] For example, when the providing unit 64 receives the service usage ID "XXXXXX" and the message "The reserved time is approaching. Reserved date and time", it identifies the "user ID: AAAA" associated with the service usage ID "XXXXXX" from the patient information DB 53. Then, the providing unit 64 uses an SNS message or the like to send the message "The reserved time is approaching. Reserved date and time" to the patient terminal 10 specified by the "user ID: AAAA".

[0055] (In-hospital server 80) As shown in FIG. 3, the in-hospital server 80 includes a communication unit 81, a storage unit 82, and a control unit 90. The communication unit 81 is a processing unit that controls communication with other devices and is realized by, for example, a communication interface or the like. For example, the communication unit 81 transmits various data to the patient terminal 10 and the mobile server 50, and receives various data from the patient terminal 10 and the mobile server 50.

[0056] The storage unit 82 is a processing unit that stores various data and programs executed by the control unit 90, and is realized by, for example, a memory or a hard disk. For example, the storage unit 82 stores a reservation information DB 83.

[0057] The reservation information DB 83 is a database that stores reservation information of patients who have reserved examinations. Specifically, the reservation information DB 83 stores the patient information that identifies the applicant, the result of authentication as to whether the patient is a legitimate patient, and information indicating whether the registration for using the mobile service has been completed, in association with each other.

[0058] FIG. 7 is a diagram showing an example of the information stored in the reservation information DB 83. As shown in FIG. 7, the reservation information DB 83 stores "patient ID, service usage ID, date of birth, reception number, application ID, authentication result, reserved medical department, reserved date and time".

[0059] The "Patient ID" stored here is an identifier that identifies Patient 1. The "Service Usage ID" is an identifier used for the use of mobile services issued to legitimate patients. The "Date of Birth" is an example of Patient 1's personal information and is input or acquired at the time of reservation. The "Reception Number" is the reception number issued to legitimate Patient 1. The "Authentication Result" is the result of authenticating that the patient is legitimate Patient 1. For example, "OK" is registered in the case of successful authentication, and "NG" is registered in the case of failed authentication. The "Reserved Department" registers the department for which Patient 1 has made a medical appointment, and the "Reservation Date and Time" registers the reservation date and time for which Patient 1 has made a medical appointment.

[0060] In the example of FIG. 7, it shows the reservation information of "Patient ID: 111" who reserved "Internal Medicine" at "14:00 on September 3, 2021". Using "Date of Birth: 19891112" and "Reception Number: 0001", etc., the authentication of that patient is permitted (OK), indicating that the service usage ID "XXXXXX" has been allocated.

[0061] The control unit 90 is a processing unit that controls the entire in-hospital server 80 and is realized by, for example, a processor or the like. This control unit 60 has a receiving unit 61, a requesting unit 62, a transmitting unit 63, and a providing unit 64. Note that the receiving unit 61, the requesting unit 62, the transmitting unit 63, and the providing unit 64 are realized by an electronic circuit of the processor, a process executed by the processor, or the like.

[0062] Here, the processing of each processing unit will also be described using the transition of the reservation information DB83 shown in FIG. 8. Note that FIG. 8 is a diagram showing the transition of the reservation information DB83.

[0063] The reservation registration unit 91 is a processing unit that registers the reservation information of a patient. Specifically, the reservation registration unit 91 receives the medical appointment of Patient 1 using a web page, an SNS message, a dedicated app, etc., and stores it in the reservation information DB83.

[0064] For example, as shown in Fig. 8(a), when the reservation registration unit 91 receives "Patient ID: 1111, Date of Birth: 19891112, Department of Internal Medicine, September 3, 2021, 14:00" as reservation information in a state where the reservation information of patient 1 is not registered in the reservation information DB 83. Then, as shown in Fig. 8(b), the reservation registration unit 91 registers the reservation information in the reservation information DB 83. Note that when reservation information or the like is received by phone or the like, the reservation registration unit 91 can also receive the input of reservation information by a clerk and register the reservation information in the reservation information DB 83.

[0065] Furthermore, when a reception ticket with a reception number "0001" printed by the re - reception machine 75 is issued, the reservation registration unit 91 obtains the association between the patient ID "1111" of the inserted examination ticket and the issued reception number "0001" from the re - reception machine 75. Then, as shown in Fig. 8(c), the reservation registration unit 91 registers the reception number "0001" in the reservation information DB 83 in association with the patient ID "1111".

[0066] The authentication unit 92 is a processing unit that executes the authentication of patient 1 based on whether the patient information received from the patient terminal 10 is registered in the reservation information DB 83. Specifically, the authentication unit 92 receives the registration information including the application ID and the patient information from the patient terminal 10 via the mobile server 50, and when the patient information has been registered in the reservation information DB 83, authenticates that it is the legitimate patient 1. In this case, the authentication unit 92 generates a service usage ID by converting the application ID into a 16 - byte hash value using a known irreversible conversion process. Then, the authentication unit 92 transmits the authentication result and the service usage ID to the mobile server 50.

[0067] On the other hand, when the received patient information is not registered in the reservation information DB 83, the authentication unit 92 determines that it is not the legitimate patient 1 and transmits an authentication rejection to the mobile server 50.

[0068] For example, in a state where reservation information is registered in the reservation information DB83 as shown in FIG. 8(c), the authentication unit 92 receives the application ID "1" and the patient information "Patient ID: 1111, Date of birth: 19891112, Reception number: 00001". In this case, since the "Patient ID: 1111, Date of birth: 19891112, Reception number: 00001" of the reservation information registered in the reservation information DB83 matches the received patient information "Patient ID: 1111, Date of birth: 19891112, Reception number: 00001", the authentication unit 92 permits the authentication.

[0069] Then, as shown in FIG. 8(d), the authentication unit 92 converts the application ID "1" into the service use ID "XXXXXX", associates it with "Patient ID: 1111", and stores the authentication result "OK" and the service use ID "XXXXXX" in the reservation information DB83. After that, the authentication unit 92 transmits the authentication result "OK" and the service use ID "XXXXXX" to the mobile server 50.

[0070] The service providing unit 93 is a processing unit that transmits a message regarding examination to the patient 1 who has already registered for the use of the mobile service. In the above example, when it becomes "September 3, 2021", the service providing unit 93 refers to the reservation information DB83 and searches for the reservation date and time of each patient. When the corresponding reservation date and time is searched, the service providing unit 93 adds the service use ID "XXXXXX" to the message "The reserved time is approaching" and transmits it to the mobile server 50.

[0071] [Flow of processing] FIG. 9 is a sequence diagram showing the flow of processing of the patient authentication system according to the first embodiment. As shown in FIG. 9, the patient terminal 10 accesses the in-hospital server 80 to execute an examination reservation (S101), and transmits reservation information "Patient ID, Date of birth, Reservation information" to the in-hospital server 80 (S102). The in-hospital server 80 registers the received reservation information in the reservation information DB83 (S103).

[0072] After that, the patient terminal 10 obtains the reception number issued by inserting the medical examination ticket into the re-reception machine 75 on the day of the medical examination reservation (S104 and S105). Then, the patient terminal 10 transmits registration information including the user ID and patient information (patient ID, date of birth, reception number) to the mobile server 50 and requests authentication and registration for using the mobile service (S106 and S107).

[0073] Then, the mobile server 50 registers the received registration information in the patient information DB53 (S108), issues an application ID for the patient and registers it in the patient information DB53 (S109). After that, the mobile server 50 deletes the patient information (patient ID, date of birth, reception number) stored in the patient information DB53 (S110), and transmits a request for use registration including the patient information (patient ID, date of birth, reception number) and the application ID to the in-hospital server 80 (S111 and S112).

[0074] Subsequently, the in-hospital server 80 receives the patient information (patient ID, date of birth, reception number) and the application ID as a request for use registration, and executes authentication of the patient 1 and use registration according to whether the patient information is registered in the reservation information DB83 (S113). When the in-hospital server 80 permits the patient 1 and use registration, it converts the application ID into a service use ID and registers it in the reservation information DB83 (S114). After that, the in-hospital server 80 transmits the application ID, the service use ID, and the authentication result to the mobile server 50 (S115 and S116).

[0075] The mobile server 50 registers the service use ID and the authentication result received from the in-hospital server 80 in the patient information DB53 (S117), and notifies the patient terminal 10 of the authentication result (S118 and S119).

[0076] As a result of the above processing, patient authentication and service registration via the mobile server 50 are normally executed between the patient 1 of the patient terminal 10 and the in-hospital server 80 (S120).

[0077] After that, when the reserved date and time approaches, the in-hospital server 80 generates a message for Patient 1 and transmits the service usage ID of the Patient 1 registered in the reservation information DB 83 and the generated message to the mobile server 50 (S121 and S122).

[0078] Then, the mobile server 50 identifies the user ID associated with the received service usage ID from the patient information DB 53 (S123), and uses the identified user ID to transmit the received message to the patient terminal 10 (S124 and S125).

[0079] As a result, the patient terminal 10 can receive and display the message from the in-hospital server 80 (S126).

[0080] Note that once Patient 1 has completed authentication and usage registration using the reception number, even if a new medical examination is reserved, there is no need to obtain a new reception number, and the mobile service can be continuously used.

[0081] FIG. 10 is a sequence diagram showing the processing flow of the patient authentication system at the time of re-reservation of a medical examination. As shown in FIG. 10, in the state where patient authentication and service registration via the mobile server 50 have been successfully completed between Patient 1 of the patient terminal 10 and the in-hospital server 80 by the processing described in FIG. 9 (S201).

[0082] In this state, the patient terminal 10 executes a new medical examination reservation (S202) and transmits new reservation information "patient ID, date of birth, new reservation date and time" to the in-hospital server 80 (S203). The in-hospital server 80 updates the reserved reservation information of the patient ID with the received new reservation information (S204).

[0083] After that, when the new reservation date and time approaches, the in-hospital server 80 generates a message for Patient 1 and transmits the service usage ID of Patient 1 registered in the reservation information DB 83 and the generated message to the mobile server 50 (S205 and S206).

[0084] Then, the mobile server 50 identifies, from the patient information DB 53, the user ID associated with the received service usage ID (S207), and uses the identified user ID to transmit the received message to the patient terminal 10 (S208 and S209).

[0085] As a result, the patient terminal 10 can receive and display a message from the in-hospital server 80 by utilizing the previously registered information even at the time of a new medical examination reservation (S210).

[0086] [Effect] As described above, the patient reservation system can simply and accurately authenticate that the person is the patient himself / herself by using the reception number on the day printed on the reception ticket issued according to the reservation information, which is the reception number on the day that can only be known by the person having the medical examination ticket and is inserted into the re-registration machine 75 when coming to the hospital on the day. Furthermore, the patient reservation system can improve the security level by further using personal information such as date of birth, My Number, and address.

[0087] The patient reservation system provides a mechanism that strengthens the method of confirming the identity by using the "reception number" that can only be received by the patient himself / herself, which is unique information within the hospital, and multi-factor authentication using cloud services at the time of receiving patients coming to the hospital, aiming to prevent patient misidentification, impersonation, and strengthen the management of personal information, and can reduce the risk of developing into a medical accident.

[0088] Since the patient reservation system does not use a new password such as a one-time password, it can reduce the trouble of password management. The patient reservation system can improve the security level by combining the medical examination ticket, reservation information, and reception number that only the patient himself / herself can know, and can also improve simplicity because it does not use a password unrelated to the medical examination reservation.

[0089] Furthermore, since the patient reservation system can achieve both simplicity and high security, the popularization of the PHR application can also be expected.

Example

[0090] Now, although the embodiments of the present invention have been described so far, the present invention may be implemented in various different forms other than the above-described embodiments.

[0091] [Numerical values, etc.] The numerical values used in the above embodiments, the number of each device, etc. are merely examples and can be arbitrarily changed. Also, the flow of the processes described in each sequence diagram, etc. can be appropriately changed within a non - conflicting range.

[0092] [Obtaining a reception number] For example, the patient terminal 10 can obtain a reception ticket by inputting a medical examination ticket into the re - reception machine 75, and can automatically input the patient ID and the reception number into the registration screen 10A by reading the two - dimensional barcode printed on the reception ticket.

[0093] [Examples of mobile services] In the above embodiments, message transmission was used as an example for explanation, but it is not limited thereto. For example, the display of the order in the waiting room, the call at the time of payment, the presentation and output of prescriptions, the management of medicines, etc. can be provided as mobile services.

[0094] [System] Regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they may be arbitrarily changed unless otherwise specified.

[0095] Also, the specific forms of distribution and integration of the components of each device are not limited to those shown in the drawings. For example, the request unit 62 and the transmission unit 63 may be integrated. That is, all or part of the components may be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc. Further, each processing function of each device may be realized by all or any part of it being realized by a CPU and a program analyzed and executed by the CPU, or may be realized as hardware by wired logic.

[0096] [Hardware] FIG. 11 is a diagram for explaining a hardware configuration example. Since the patient terminal 10, the mobile server 50, and the in-hospital server 80 have the same hardware configuration, here, it will be described as the information processing apparatus 100. As shown in FIG. 11, the information processing apparatus 100 includes a communication device 100a, an HDD (Hard Disk Drive) 100b, a memory 100c, and a processor 100d. Also, each part shown in FIG. 11 is mutually connected by a bus or the like.

[0097] The communication device 100a is a network interface card or the like and communicates with other devices. The HDD 100b stores programs and databases for operating the functions shown in FIG. 3.

[0098] The processor 100d reads a program for executing the same processing as each processing unit shown in FIG. 3 from the HDD 100b or the like and expands it in the memory 100c, thereby operating a process for executing each function described in FIG. 3 or the like. For example, taking the mobile server 50 as an example, this process executes the same functions as each processing unit of the mobile server 50. Specifically, the processor 100d reads a program having the same functions as the reception unit 61, the request unit 62, the transmission unit 63, the provision unit 64, etc. from the HDD 100b or the like. Then, the processor 100d executes a process for executing the same processing as the reception unit 61, the request unit 62, the transmission unit 63, the provision unit 64, etc.

[0099] In this way, the information processing apparatus 100 operates as an information processing apparatus that executes an information processing method by reading and executing a program. Further, the information processing apparatus 100 can also realize the same functions as those in the above-described embodiments by reading the program from the recording medium by the medium reading apparatus and executing the read program. Note that the program in this other embodiment is not limited to being executed by the information processing apparatus 100. For example, the above-described embodiments may be similarly applied when another computer or server executes the program, or when these cooperate to execute the program.

[0100] This program may be distributed via a network such as the Internet. Further, this program may be recorded on a computer-readable recording medium such as a hard disk, a flexible disk (FD), a CD-ROM, a MO (Magneto-Optical disk), a DVD (Digital Versatile Disc), and may be executed by being read from the recording medium by a computer.

Description of Reference Numerals

[0101] 10 Patient terminal 11 Communication unit 12 Display unit 13 Storage unit 20 Control unit 21 Registration unit 22 Usage control unit 50 Mobile server 51 Communication unit 52 Storage unit 53 Patient information DB 60 Control unit 61 Reception unit 62 Request unit 63 Transmission unit 64 Provision unit 80 In-hospital server 81 Communication unit 82 Storage unit 83 Reservation information DB 90 Control unit 91 Reservation Registration Section 92 Authentication Section 93 Service Provision Section

Claims

1. A receiving unit that receives patient information including an identifier for identifying the patient and a reception number issued by the hospital upon receiving the patient at a patient terminal used by a patient who has reserved a medical examination at the hospital; A requesting unit that transmits the patient information to an in-hospital server that manages reservation information regarding the person who reserved the medical examination and requests authentication that the patient is the person who reserved the medical examination; A transmitting unit that transmits the authentication result by the in-hospital server to the patient terminal; An information processing apparatus having the above.

2. The information processing apparatus according to claim 1, wherein the reception number is a reception number issued by inserting the patient's medical examination ticket into a reception machine installed at the hospital and given to the patient on the day of the medical examination.

3. The requesting unit: Requests the in-hospital server to register for use of a mobile service related to the medical examination together with the authentication; The transmitting unit: As a response to the request to register for use of the mobile service related to the medical examination, when receiving service use information issued by the in-hospital server when the in-hospital server has registered the patient information from the in-hospital server, notifies the patient terminal of permission to use the mobile service. The information processing apparatus according to claim 1 or 2.

4. The receiving unit: Receives the patient information further including personal information for identifying the patient; The requesting unit: Transmits the patient information to the in-hospital server and requests registration for use of the mobile service; The transmitting unit: When receiving the service use information issued by the in-hospital server when the in-hospital server has registered the patient information from the in-hospital server, notifies the patient terminal of permission to use the mobile service. The information processing apparatus according to claim 3.

5. The requesting unit: Assigns an application number to the patient information received from the patient terminal, associates the patient information and the application number, stores them as registration information in a storage unit, Transmits the registration information to the in-hospital server and requests issuance of the service use information, and deletes the identifier and the reception number among the patient information stored in the storage unit; The transmitting unit: Receives the service use information and the application number from the in-hospital server, stores the service use information in the storage unit in association with the application number, and notifies the patient terminal of permission to use the mobile service. The information processing apparatus according to claim 3 or 4.

6. Receive the service usage information and the message to the patient from the in-hospital server, Refer to the storage unit to identify the patient terminal associated with the service usage information, The information processing apparatus according to claim 5, further comprising a providing unit that transmits the message to the identified patient terminal.

7. A computer Receives patient information including an identifier for identifying the patient and a reception number issued by the hospital when the patient who reserved a medical examination at the hospital uses the patient terminal, Transmits the patient information to an in-hospital server that manages reservation information regarding the person who reserved the medical examination, and requests authentication that the patient is the one who reserved the medical examination, Transmits the authentication result by the in-hospital server to the patient terminal, An authentication method for executing the process.

8. A computer Receives patient information including an identifier for identifying the patient and a reception number issued by the hospital when the patient who reserved a medical examination at the hospital uses the patient terminal, Transmits the patient information to an in-hospital server that manages reservation information regarding the person who reserved the medical examination, and requests authentication that the patient is the one who reserved the medical examination, Transmits the authentication result by the in-hospital server to the patient terminal, An authentication program for executing the process.

9. In an information processing system having a patient terminal used by a patient who reserved a medical examination at a hospital, an in-hospital server that manages reservation information regarding the person who reserved the medical examination, and an information processing apparatus that relays communication between the patient terminal and the in-hospital server, The patient terminal Has a transmission unit that transmits patient information including an identifier for identifying the patient and a reception number issued by the hospital when the patient receives the information to the information processing apparatus, The information processing apparatus A request unit that transmits the patient information received from the patient terminal to the in-hospital server and requests registration for using the mobile service related to the medical examination, A transmission unit that transmits the result of the use registration by the in-hospital server to the patient terminal, The in-hospital server Has a storage unit that stores reservation information regarding the person who reserved the medical examination, When the patient information is registered in the reservation information, has a notification unit that executes registration for using the mobile service and notifies the information processing apparatus of the result of the use registration, A patient authentication system.

Citation Information

Patent Citations

  • Time designation medical examination reservation system

    JP2010267120A

  • Information processing device, and method and program for controlling information processing device

    JP2015064832A

  • Patient information management system, and reception device to be used in the patient information management system

    JP2017151732A

  • Patient registration method for outpatient guide system

    JP2019074870A

  • Medical facility reception system

    JP2020057174A